CVE Database
/

CVE-2023-25556

Back to search

CVE-2023-25556

Published: Apr 18, 2023

Modified: Feb 5, 2025

PUBLISHED

CVSS v3.1

8.3

HIGH

Description

A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.

VendorProductVersions

Schneider Electric

Merten INSTABUS Tastermodul 1fach System M 625199

affected
Program Version 1.0

Schneider Electric

Merten INSTABUS Tastermodul 2fach System M 625299

affected
Program Version 1.0

Schneider Electric

Merten Tasterschnittstelle 4fach plus 670804

affected
Program Version 1.0
affected
Program Version 1.2

Schneider Electric

Merten KNX ARGUS 180/2,20M UP SYSTEM 631725

affected
Program Version 1.0

Schneider Electric

Merten Jalousie-/Schaltaktor REG-K/8x/16x/10 m. HB 649908

affected
Program Version 1.0

Schneider Electric

Merten KNX Uni-Dimmaktor LL REG-K/2x230/300 W MEG6710-0002

affected
Program Version 1.0
affected
Program Version 1.1

Schneider Electric

Merten KNX Schaltakt.2x6A UP m.2 Eing. MEG6003-0002

affected
Program Version 0.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now